As cyberspace becomes an ever more integrated part of daily life, cybersecurity has become a central part of the national defense. Acknowledging this, Defense Secretary nominee Ash Carter was asked several pointed questions about cyber threats and creating a framework for appropriate responses to attacks.
“An effective deterrence strategy requires a range of cyber policies and capabilities to affect a state or non-state actors’ behavior,” Carter wrote in an Advance Policy Questionnaire for the Senate Armed Services Committee. “In addition to continuing efforts to improve U.S. cyber defenses and cybersecurity capabilities, the United States should continue to respond to cyber attacks against U.S. interests at a time, in a manner and in a place of our choosing, using appropriate instruments of U.S. power and in accordance with applicable law.”

More: Ash Carter tapped as next defense secretary
“Deterrence cannot be achieved through cyberspace alone, but requires a multi-faceted effort across the totality of the U.S. government’s instruments of national power, including network defense measures, economic actions, law enforcement actions, defense posture and response capabilities, intelligence, declaratory policy and the overall resiliency of U.S. networks and systems,” he wrote.
A recent report from Indiana University of Pennsylvania and the IBM Center for the Business of Government looked to define cyberspace as a strategic domain and came to many of the same conclusions as Carter.
The reports notes that, unlike the other four domains — land, sea, air and space — cyberspace does not have any boundaries and “permeates the entire strategic environment and also encompasses the other strategic domains.”
Report: Defining a Framework for Decision Making in Cyberspace
Similarly, the threats posed by actors in cyberspace can manifest in both the cyber and physical realms.
“Traditional security threats come from within the physical sphere and response was and often is delivered in that sphere as well, but the cyber sphere can be used to augment a physical sphere response,” the report states.
Leaving behind the traditional view, Carter identified a modern “act of war” as anything that compromises the nation’s critical infrastructure, economy or military operations.

“I believe that what is termed an act of war should follow the same practices as in other domains because it is the seriousness, not the means of an attack that matters most,” he wrote. “Malicious cyber activities could result in death, injury or significant destruction, and any such activities would be regarded with the utmost concern and could well be considered ‘acts of war.’”
Carter said the recent attacks on Sony, attributed to North Korea, did not “rise to the level of an ‘act of war,’” though it did merit an appropriate response.
“An attack does not need to be deemed an ‘act of war’ to require a response,” he said, though it should be appropriately calibrated.
“Managing security in cyberspace is not a narrow technical challenge; it involves fundamental issues of politics and strategy, nation-state relations, bargaining, and escalation dynamics and control,” researchers wrote.
Coming up with a measured response to cyber attacks is complicated, they said, and near impossible without a cohesive strategy.
“Without a solid conceptual foundation, a cyber conflict would pose significant management challenges,” the report states. “Even with more comprehensive scenario development and contingency planning, there is strong potential for miscalculations and misunderstandings that provoke an out-of-control escalatory spiral, absent a commonly understood definitional framework to help frame strategic and tactical choices.”
The report recommends the government create a specific definition of cyberspace in a security context; recognize cyber as a strategic domain; and improve education on managing cyber risk and response options.
“I believe a whole-of-government approach is required to address the cyber threats we face now and will increasingly face in the future,” Carter wrote. “The Department of Defense must continue to work closely with the Department of Homeland Security, the Department of Justice (specifically FBI) and the Intelligence Community, as well as with other federal partners to identify, mitigate and defend against cyber threats.”




